Description

On trying to download 1.9.16 and 2.2 latest version on Friday (20th Jan) our Sophos antivirus reported that the server the packages were downloading from had issues with trojans and blocked the download. I asked a question on Moodle.org and Mauno suggested filing an issue as the link was going to a server that had previously had issues. We are running Sophos Endpoint Security and Control v10

Most likely yes - so even if the files of moodle are clean Sourceforge is using subservers like freefr.dl.sourceforge.net or garr.dl.sourceforge.net with .../download?use_mirror=freefr and .../download?use_mirror=garr and these mirrorservers have (had) different trojans - and Sophos blocks access to those mirror sites.

Mauno Korpelainen
added a comment - 25/Jan/12 2:36 AM Most likely yes - so even if the files of moodle are clean Sourceforge is using subservers like freefr.dl.sourceforge.net or garr.dl.sourceforge.net with .../download?use_mirror=freefr and .../download?use_mirror=garr and these mirrorservers have (had) different trojans - and Sophos blocks access to those mirror sites.
McAfee and Siteadvisor report some trojans there too - see http://www.siteadvisor.com/sites/freefr.dl.sourceforge.net/downloads/ and http://www.siteadvisor.com/sites/garr.dl.sourceforge.net/downloads/ - but obviously Sophos is the first antivirus program blocking download on this basis.

Michael de Raadt
added a comment - 04/Feb/12 3:39 PM Well, I didn't receive any response from Sophos, but it looks like contacting the did the trick.
If there are any similar future problems, please launch a new issue.